Description
Improper input validation in Viz in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-10-06
Score: n/a
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

Improper input validation in Chrome’s Viz rendering component allows an attacker who has already compromised the renderer process to bypass system access restrictions by loading a specially crafted HTML page. The vulnerability does not depend on additional user interaction and can enable elevated privileges or unauthorized access to local resources from a web page.

Affected Systems

The issue affects Google Chrome versions earlier than 155.0.8059.39. Users running these builds on any platform are susceptible because the renderer process is granted higher privileges than regular web content.

Risk and Exploitability

The vulnerability carries a medium severity rating and is not listed in the CISA KEV catalog. EPSS data is not available, so the exact probability of exploitation is unknown. The likely attack vector is remote: an attacker who can execute code in the renderer, such as through a malicious website or compromised local content, can craft an HTML payload that triggers the improper validation and lifts the access restrictions. The attacker would need to deliver the payload to a compromised renderer, after which the system access boundaries can be bypassed.

Generated by OpenCVE AI on October 6, 2026 at 21:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Chrome to version 155.0.8059.39 or later; this release contains a fix that validates all rendered input correctly.
  • If immediate update is not possible, disable privileged renderer processes by configuring Chrome to run in kiosk or sandbox mode with the minimal permissions required.
  • Avoid loading untrusted or unknown web content that could host crafted HTML; consider network or content filtering to block malicious sites.

Generated by OpenCVE AI on October 6, 2026 at 21:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Title Remote Attacker Can Bypass System Access Restrictions via Crafted HTML in Chrome Renderer Process

Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Improper input validation in Viz in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-20
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T18:41:19.755Z

Reserved: 2026-10-06T16:30:21.721Z

Link: CVE-2026-106185

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:17:44.510

Modified: 2026-10-06T19:58:37.060

Link: CVE-2026-106185

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T21:15:06Z

Weaknesses
  • CWE-20

    Improper Input Validation